CVE-2026-29610
CVE-2026-29610
7.7
HighPublished:
Last updated:
Source:disclosure@vulncheck.com
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- Present
- Privileges Required
- Low
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to node-host execution surfaces or those running OpenClaw in attacker-controlled directories can place malicious executables in PATH to override allowlisted safe-bin commands and achieve arbitrary command execution.
References
disclosure@vulncheck.com
https://github.com/openclaw/openclaw/commit/013e8f6b3be3333a229a066eef26a45fec47ffccdisclosure@vulncheck.com
https://github.com/openclaw/openclaw/security/advisories/GHSA-jqpq-mgvm-f9r6disclosure@vulncheck.com
https://www.vulncheck.com/advisories/openclaw-command-hijacking-via-unsafe-path-handling